Welchia Removal Tool icon

Welchia Removal Tool

4.7/5 9
Certified 100% CLEAN Freeware   

Erase the Welchia virus from your computer #Welchia antivirus  #Welchia remover  #Welchia worm  #Welchia  #Antivirus  #Remover  

Description

Free Download

Welchia Removal Tool is a small yet effective means of cleaning the Win32.Worm.Welchia malware.

For Windows XP systems, it uses the Windows DCOM RPC vulnerability described in MS03-026 security bulletin, to infect new computers.

For systems that have the IIS service, it uses the Windows WebDav vulnerability described in MS03-007 security bulletin, to infect new computers.

When ran it looks for Win32.Msblast.A worm file (msblast.exe) and tries to remove it from the computer. It also attempts to download the patch for the DCOM RPC vulnerability and to install it. If it successfully installs it, it restarts the computer without notice.

After infecting a remote computer, it opens a random TCP port between 666 and 765, on the remote computer so as to send commands to it.

It uses the TFTP file transfer protocol to copy the worm body: dllhost.exe, and the TFTP server: tftpd.exe, that will be renamed to svchost.exe after copying in %system32%\wins.

It creates two services: Network Connections Sharing with the path to executable: %system32%\wins\svchost.exe and WINS Client with the path to executable: %system32%\wins\dllhost.exe, that are set to run automatically, so that the worm will be active, even if no user is logged on the computer.

The worm contains some text strings: I love my wife & baby :), Welcome Chian, Notice: 2004 will remove myself:) and sorry zhongli. It is true, from the year 2004 it would uninstall itself from the infected machine.

The mutex that it uses not to run twice on the same computer is named RpcPatch_Mutex.

add to watchlist add to download basket send us an update REPORT
  runs on:
Windows All
  file size:
58 KB
  filename:
antiwelchia-en.exe
  1 screenshot:
Welchia Removal Tool - Welchia Removal Tool will scan and remove the virus infection immediately.
  main category:
Antivirus
  developer:
  visit homepage

Bitdefender Antivirus Free

Feather-light and free antivirus solution from renowned developer that keeps the PC protected at all times from malware without requiring user configuration
Bitdefender Antivirus Free

Microsoft Teams

Effortlessly chat, collaborate on projects, and transfer files within a business-like environment by employing this Microsoft-vetted application
Microsoft Teams

IrfanView

With support for a long list of plugins, this minimalistic utility helps you view images, as well as edit and convert them using a built-in batch mode
IrfanView

Context Menu Manager

Customize Windows’ original right-click context menu using this free, portable and open-source utility meant to enhance your workflow
Context Menu Manager

ShareX

Capture your screen, create GIFs, and record videos through this versatile solution that includes various other amenities: an OCR scanner, image uploader, URL shortener, and much more
ShareX

7-Zip

An intuitive application with a very good compression ratio that can help you not only create and extract archives, but also test them for errors
7-Zip

calibre

Effortlessly keep your e-book library thoroughly organized with the help of the numerous features offered by this efficient and capable manager
calibre

4k Video Downloader

Export your favorite YouTube videos and playlists with this intuitive, lightweight program, built to facilitate downloading clips from the popular website
4k Video Downloader

Zoom Client

The official desktop client for Zoom, the popular video conferencing and collaboration tool used by millions of people worldwide
Zoom Client

Windows Sandbox Launcher

Set up the Windows Sandbox parameters to your specific requirements, with this dedicated launcher that features advanced parametrization
Windows Sandbox Launcher

% discount
4k Video Downloader
  • 4k Video Downloader
  • Zoom Client
  • Windows Sandbox Launcher
  • Bitdefender Antivirus Free
  • Microsoft Teams
  • IrfanView
  • Context Menu Manager
  • ShareX
  • 7-Zip
  • calibre
essentials


Click to load comments
This enables Disqus, Inc. to process some of your data. Disqus privacy policy